Skip to content
VulniPulse

Palo Alto Networks Security Advisories & CVEs

85 advisories tracked · Palo Alto Networks Security Advisories · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Palo Alto CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Palo Alto device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Palo Alto's recent advisories.

Official source

Palo Alto Networks Security Advisories

Polled via the official security.paloaltonetworks.com RSS feed. Advisory pages are fetched for new items to extract affected/fixed version tables.

Latest Palo Alto advisories

HighPalo Alto Exploited CISA KEV

High [CVE-2026-0275 +529] PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)

PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026)

CVE-2026-0275CVE-2026-10881CVE-2026-10882+527
Unclassified
Jul 8, 2026
Medium5.9Vendor: LowPalo Alto

Medium [CVE-2026-0281] PAN-OS: Information Disclosure Vulnerability in Management Web Interface

CVE-2026-0281 PAN-OS: Information Disclosure Vulnerability in Management Web Interface

CVE-2026-0281
PAN-OSFirewallPAN-OS / Panorama
Jul 8, 2026
Medium5.3Vendor: LowPalo Alto

Medium [CVE-2026-0279] PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities

CVE-2026-0279 PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities Affected products named by the advisory: Prisma Access.

CVE-2026-0279
PAN-OSFirewallPrisma AccessPAN-OS / Panorama
Jul 8, 2026
Medium4.8Vendor: LowPalo Alto

Medium [CVE-2026-0276] Cortex XDR Broker VM: Privilege Escalation (PE) Vulnerability

CVE-2026-0276 Cortex XDR Broker VM: Privilege Escalation (PE) Vulnerability

CVE-2026-0276
Cortex
Jul 8, 2026
Medium6.3Vendor: LowPalo Alto

Medium [CVE-2026-0280] PAN-OS: IPv6 Firewall Policy Bypass

CVE-2026-0280 PAN-OS: IPv6 Firewall Policy Bypass Affected products named by the advisory: Prisma Access.

CVE-2026-0280
PAN-OSFirewallPrisma AccessPAN-OS / Panorama
Jul 8, 2026
Medium6.9Vendor: LowPalo Alto

Medium [CVE-2026-0282] PAN-OS: File Deletion Vulnerability in Management Web Interface

CVE-2026-0282 PAN-OS: File Deletion Vulnerability in Management Web Interface

CVE-2026-0282
PAN-OSFirewallPAN-OS / Panorama
Jul 8, 2026
High7.6Vendor: MediumPalo Alto

High [CVE-2026-0249] GlobalProtect App: Certificate Validation Bypass Vulnerabilities

CVE-2026-0249 GlobalProtect App: Certificate Validation Bypass Vulnerabilities

CVE-2026-0249
GlobalProtect
Jun 13, 2026
High7.7Vendor: MediumPalo Alto

High [CVE-2026-0250] GlobalProtect App: Buffer Overflow Vulnerability during connection to Portal or Gateway

CVE-2026-0250 GlobalProtect App: Buffer Overflow Vulnerability during connection to Portal or Gateway

CVE-2026-0250
GlobalProtect
Jun 13, 2026
Medium4.0Palo Alto

Medium [CVE-2026-45169] Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a…

Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized denial of service (DoS). CyberArk Security Bulletin: CA26-17 Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CNA: Palo Alto Networks, Inc. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriat

CVE-2026-45169
Unclassified
Jun 12, 2026
Medium4.0Vendor: HighPalo Alto

Medium [CVE-2026-45170] Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS…

Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bulletin: CA26-17

CVE-2026-45170
Unclassified
Jun 12, 2026
High8.6Vendor: MediumPalo Alto

High [CVE-2026-0273] PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI

CVE-2026-0273 PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI

CVE-2026-0273
PAN-OSFirewallPAN-OS / Panorama
Jun 11, 2026
Medium4.0Vendor: HighPalo Alto

Medium [CVE-2026-45174] Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5

Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the agent daemon initialization. CyberArk Security Bulletin: CA26-19 Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CNA: Palo Alto Networks, Inc. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be

CVE-2026-45174
Unclassified
Jun 11, 2026
Medium4.0Palo Alto

Medium [CVE-2026-45173] Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw…

Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If an authenticated user navigates to a specially crafted webpage, this interaction could potentially allow a remote attacker to trigger unauthorized application interaction or execution parameters within the context of that authenticated browser session. CyberArk Security Bulletin: CA26-21 Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CNA: Palo Alto Networks, Inc. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites

CVE-2026-45173
Unclassified
Jun 11, 2026
Medium4.0Vendor: HighPalo Alto

Medium [CVE-2026-45172] Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5…

Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0.6, an authenticated, low-privileged user could potentially execute arbitrary commands on the PSMP host. CyberArk Security Bulletins: CA26-17 and CA26-18 Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CNA: Palo Alto Networks, Inc. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur wit

CVE-2026-45172
Unclassified
Jun 11, 2026
Medium4.0Vendor: HighPalo Alto

Medium [CVE-2026-45171] Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions…

Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5, an authenticated, low-privileged user could potentially execute arbitrary code. CyberArk Security Bulletin: CA26-17 and CA26-18 Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CNA: Palo Alto Networks, Inc. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expresse

CVE-2026-45171
Unclassified
Jun 11, 2026
Medium4.0Vendor: HighPalo Alto

Medium [CVE-2026-45175] Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation…

Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumstances, this could allow the attacker to circumvent agent self-defense mechanisms and execute unauthorized operations. CyberArk Security Bulletin: CA26-19 Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CNA: Palo Alto Networks, Inc. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be othe

CVE-2026-45175
Unclassified
Jun 11, 2026
Medium4.0Vendor: HighPalo Alto

Medium [CVE-2026-45178] Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints

Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially retrieve unauthorized secrets or cause a denial of service (DoS). CyberArk Security Bulletin: CA26-20 Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CNA: Palo Alto Networks, Inc. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose.

CVE-2026-45178
Unclassified
Jun 11, 2026
Medium4.0Vendor: CriticalPalo Alto

Medium [CVE-2026-45177] Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication…

Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted request. Under specific circumstances, this could allow the attacker to manipulate internal validation mechanisms, potentially leading to a bypass of identity verification and the unauthorized acquisition of an access token. CyberArk Security Bulletin: CA26-20 Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CNA: Palo Alto Networks, Inc. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on accoun

CVE-2026-45177
Unclassified
Jun 11, 2026
Medium4.0Vendor: HighPalo Alto

Medium [CVE-2026-45176] Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent…

Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal communication mechanism or file operation. Under specific circumstances, this could potentially allow the attacker to bypass permission restrictions and execute unauthorized local actions with elevated privileges. CyberArk Security Bulletin: CA26-19 Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed. CVSS 4.0 Severity and Vector Strings: NIST: NVD N/A NVD assessment not yet provided. CNA: Palo Alto Networks, Inc. References to Advisories, Solutions, and Tools By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being re

CVE-2026-45176
Unclassified
Jun 11, 2026
Critical9.3Vendor: HighPalo Alto

Critical [CVE-2026-0274] Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration

CVE-2026-0274 Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration

CVE-2026-0274
Cortex
Jun 10, 2026

← All vendors